Growi
by Weseek
Source repositories
CVEs (44)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-43880 | Med | 0.21 | 4.3 | 0.00 | Jun 25, 2025 | Inefficient regular expression complexity issue exists in GROWI prior to v7.1.6. If exploited, a logged-in user may cause a denial of service (DoS) condition. | ||
| CVE-2021-20668 | Low | 0.18 | 2.7 | 0.01 | Mar 10, 2021 | Path traversal vulnerability in GROWI versions v4.2.2 and earlier allows an attacker with administrator rights to read an arbitrary path via a specially crafted URL. | ||
| CVE-2022-1236 | Med | 0.00 | 6.5 | 0.01 | Apr 5, 2022 | Weak Password Requirements in GitHub repository weseek/growi prior to v5.0.0. | ||
| CVE-2021-3852 | Hig | 0.00 | 7.5 | 0.01 | Jan 12, 2022 | growi is vulnerable to Authorization Bypass Through User-Controlled Key |
- risk 0.21cvss 4.3epss 0.00
Inefficient regular expression complexity issue exists in GROWI prior to v7.1.6. If exploited, a logged-in user may cause a denial of service (DoS) condition.
- risk 0.18cvss 2.7epss 0.01
Path traversal vulnerability in GROWI versions v4.2.2 and earlier allows an attacker with administrator rights to read an arbitrary path via a specially crafted URL.
- risk 0.00cvss 6.5epss 0.01
Weak Password Requirements in GitHub repository weseek/growi prior to v5.0.0.
- risk 0.00cvss 7.5epss 0.01
growi is vulnerable to Authorization Bypass Through User-Controlled Key
Page 3 of 3